CyberEssentials

UK baseline technical controls for reducing common cyber threats.

Cyber Essentials is a UK technical standard that defines a minimum set of controls for basic cyber hygiene. It focuses on device configuration, patching, user access and boundary protection.

It is practical but limited in scope. Implementing it highlights gaps in patch management, asset inventory and change control, and certification requires evidence and ongoing maintenance.

Cyber Essentials — access, authentication and privileged controls

Specifies baseline controls for restricting access, enforcing authentication and managing privileged accounts to reduce common attack vectors.

Cyber Essentials — audit evidence

Collected logs, reports and records that demonstrate controls meet Cyber Essentials requirements and support audit review.

Cyber Essentials: governance, oversight and accountability

Provides baseline controls to support oversight, policy enforcement and evidence for compliance and risk management.

Where CyberEssentials fits

The standard maps to endpoints, firewalls, email gateways and cloud service configurations. Those components need consistent settings and inventories to make the controls effective.

Treat Cyber Essentials as a baseline technical standard when planning controls or checking suppliers. It does not replace a wider risk assessment or higher assurance requirements.

Discuss your CyberEssentials implementation